US2024364704A1PendingUtilityA1

Time bound session management for Operational Technology (OT) applications

Assignee: ZSCALER INCPriority: Apr 29, 2023Filed: Jun 16, 2023Published: Oct 31, 2024
Est. expiryApr 29, 2043(~16.8 yrs left)· nominal 20-yr term from priority
H04L 63/20H04L 63/102H04L 63/108H04L 67/143
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for time bound session management for Operational Technology (OT) applications using Cron expression policies over zero trust. Various embodiments include receiving a request to an end system from a user; determining that the request requires a time-based approval; performing one or more time-based policy checks associated with the request; and allowing or denying the request based on the one or more time-based policy checks. The steps can further include monitoring an active session between the user and the end system; and timing out the active session based on time-based policy checks.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising steps of:
 receiving a request to an end system from a user;   determining that the request requires a time-based approval;   performing one or more time-based policy checks associated with the request; and   allowing or denying the request based on the one or more time-based policy checks.   
     
     
         2 . The method of  claim 1 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system. 
     
     
         3 . The method of  claim 1 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user. 
     
     
         4 . The method of  claim 3 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied. 
     
     
         5 . The method of  claim 1 , wherein the steps further include displaying one or more end systems to the user through a portal. 
     
     
         6 . The method of  claim 5 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy. 
     
     
         7 . The method of  claim 1 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems. 
     
     
         8 . The method of  claim 7 , wherein the configuring is performed through calendar based selections for designating allowed time windows. 
     
     
         9 . The method of  claim 1 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window. 
     
     
         10 . The method of  claim 1 , wherein the steps further comprise:
 monitoring an active session between the user and the end system; and   timing out the active session based on time-based policy checks.   
     
     
         11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:
 receiving a request to an end system from a user;   determining that the request requires a time-based approval;   performing one or more time-based policy checks associated with the request; and   allowing or denying the request based on the one or more time-based policy checks.   
     
     
         12 . The non-transitory computer-readable medium of  claim 11 , wherein the one or more time-based policy checks are associated with any of the user and the requested end system. 
     
     
         13 . The non-transitory computer-readable medium of  claim 11 , wherein the one or more time-based policy checks include looking up approval tables based on an identity of the user. 
     
     
         14 . The non-transitory computer-readable medium of  claim 13 , wherein responsive to no match being found in the approval tables, or if an appropriate approval table does not exist, the request is denied. 
     
     
         15 . The non-transitory computer-readable medium of  claim 11 , wherein the steps further include displaying one or more end systems to the user through a portal. 
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein the one or more end systems are marked as active, inactive, or expired based on time-based policy. 
     
     
         17 . The non-transitory computer-readable medium of  claim 11 , wherein the steps further include configuring time-based policies associated with any of a user, group of users, and specific end systems. 
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein the configuring is performed through calendar based selections for designating allowed time windows. 
     
     
         19 . The non-transitory computer-readable medium of  claim 11 , wherein the one or more time-based policy checks include comparing a current time against a Coordinated Universal Time (UTC) start and end time of a given time window. 
     
     
         20 . The non-transitory computer-readable medium of  claim 11 , wherein the steps further comprise:
 monitoring an active session between the user and the end system; and   timing out the active session based on time-based policy checks.

Join the waitlist — get patent alerts

Track US2024364704A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.